Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 20.206.176.5:443 ยท assinador.uel.br
2026-01-22 23:28
HTTP/1.1 200 OK Connection: close Content-Type: text/html Date: Thu, 22 Jan 2026 23:29:04 GMT Server: Kestrel Accept-Ranges: bytes Cache-Control: no-cache, no-store, must-revalidate ETag: "1dc502817a7da0c" Expires: -1 Last-Modified: Fri, 07 Nov 2025 20:50:04 GMT Set-Cookie: ARRAffinity=49423cf21a7c8f31473ef02d2227745c0c400eef47ec6f4bd5f71cd68d6585b4;Path=/;HttpOnly;Secure;Domain=assinador.uel.br Set-Cookie: ARRAffinitySameSite=49423cf21a7c8f31473ef02d2227745c0c400eef47ec6f4bd5f71cd68d6585b4;Path=/;HttpOnly;SameSite=None;Secure;Domain=assinador.uel.br Transfer-Encoding: chunked